CVE-2022-39261
Summary
| CVE | CVE-2022-39261 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-28 14:15:00 UTC |
| Updated | 2023-11-07 03:50:00 UTC |
| Description | Twig is a template language for PHP. Versions 1.x prior to 1.44.7, 2.x prior to 2.15.3, and 3.x prior to 3.4.3 encounter an issue when the filesystem loader loads templates for which the name is a user input. It is possible to use the `source` or `include` statement to read arbitrary files from outside the templates' directory when using a namespace like `@somewhere/../some.file`. In such a case, validation is bypassed. Versions 1.44.7, 2.15.3, and 3.4.3 contain a fix for validation of such template names. There are no known workarounds aside from upgrading. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 35 Update: php-twig2-2.15.3-1.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] [DLA 3147-1] twig security update |
MLIST |
lists.debian.org |
|
| [SECURITY] Fedora 37 Update: php-twig-1.44.7-1.fc37 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Access to this page has been denied. |
CONFIRM |
www.drupal.org |
|
| [SECURITY] Fedora 36 Update: php-twig-1.44.7-1.fc36 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 35 Update: php-twig-1.44.7-1.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 37 Update: php-twig2-2.15.3-1.fc37 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| security #cve- Fix a security issue on filesystem loader (possibility… · twigphp/Twig@35f3035 · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 35 Update: php-twig2-2.15.3-1.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Debian -- Security Information -- DSA-5248-1 php-twig |
DEBIAN |
www.debian.org |
|
| [SECURITY] Fedora 37 Update: php-twig2-2.15.3-1.fc37 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 35 Update: php-twig-1.44.7-1.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 36 Update: php-twig2-2.15.3-1.fc36 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 37 Update: php-twig-1.44.7-1.fc37 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 36 Update: php-twig-1.44.7-1.fc36 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Possibility to load a template outside a configured directory when using the filesystem loader · Advisory · twigphp/Twig · GitHub |
CONFIRM |
github.com |
|
| [SECURITY] Fedora 36 Update: php-twig2-2.15.3-1.fc36 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 154123 Drupal Core: Twig Template Path Traversal Vulnerability (CVE-2022-39261)
- 181128 Debian Security Update for twig (DLA 3147-1)
- 184290 Debian Security Update for php-twig (CVE-2022-39261)
- 199472 Ubuntu Security Notification for Twig Vulnerabilities (USN-5947-1)
- 283183 Fedora Security Update for Hypertext Preprocessor (PHP) (FEDORA-2022-d39b2a755b)
- 283184 Fedora Security Update for Hypertext Preprocessor (PHP) (FEDORA-2022-9d8ee4a6de)
- 283186 Fedora Security Update for Hypertext Preprocessor (PHP) (FEDORA-2022-4490a4772d)
- 283187 Fedora Security Update for Hypertext Preprocessor (PHP) (FEDORA-2022-1695454935)
- 730620 Drupal Core Multiple vulnerabilities Vulnerability (SA-CORE-2022-016)